PT-2026-83553 · Dolibarr · Dolibarr

·

CVE-2026-82633

·

Published

2026-08-30

·

Updated

2026-08-30

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Dolibarr versions 10.0.0 through 23.0.0
Description Authenticated users can retrieve group memberships of other users because the software fails to perform per-object authorization checks. By calling the 'GET /users/{id}/groups' API endpoint with arbitrary id values, an attacker can access group names, entity associations, and private notes across tenant boundaries.
Recommendations Update to version 24.0.0 or later. Restrict access to the 'GET /users/{id}/groups' API endpoint to minimize the risk of unauthorized data retrieval.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82633

Affected Products

Dolibarr